NCC Group logo

NCC Group Cybersecurity Consultant Interview Questions
& Process

Real candidates share what happened, how many rounds they had,
and how the experience turned out.

Based on 23 interview experiences · FREE TO READ

2.9 Rounds average
Average Typical difficulty
78.3% Positive experience

Candidate interview experiences

First-hand accounts from people who interviewed at NCC Group.

Showing 3 of 23
NCC Group logo
NCC Group

Cyber Security Consultant

Consulting · a year ago

Senior Average Negative experience Accept offer 1 round
Interview process
Recruiter call Background check Offer
Interview formats
Behavioral

I interviewed with NCC Group. The interview ended with a formal offer being made on the call. However, a week later, the TA manager called to say I was unsuccessful, which was shocking and disappointing.

Confirmed questions0 questions

No confirmed questions were included in this interview report.

NCC Group logo
NCC Group

Security Consultant

Consulting

Entry Average Positive experience Accept offer 2 rounds
Interview process
Recruiter call Take home Technical screen Onsite Offer
Interview formats
Technical Coding

The hiring process, which lasted about two months from the first call to the offer, felt pretty smooth, even with holidays. The recruiter kept me updated and gave feedback on time. After the initial call, I had to do a web pentesting challenge. I submitted it twice because the first report wasn't detailed enough. It took about 3-4 weeks (due to holidays) to hear back that I passed and would move to the first interview. This interview was pretty chill; the interviewers were nice and asked about my background and some technical stuff. The next day, I found out I passed and was moving to the final interview. The second interview was more in-depth technically but still enjoyable. About a week later, I got the offer!

Confirmed questions6 questions
  • Regarding the OWASP Top 10, can you walk me through a scenario with broken access and XSS, and what are the mitigation strategies?
  • From the perspective of a regular domain user, describe the complete process of exploiting Active Directory.
  • Could you explain the distinctions between the SYSTEM and Administrator accounts?
NCC Group logo
NCC Group

Security Consultant

Engineering

Mid Average Positive experience Accept offer 2 rounds
Interview process
Recruiter call Technical screen Onsite
Interview formats
Behavioral Technical Coding

I went to London for a couple of interviews and NCC was one of them. The first interview was a face-to-face talk with the Director to understand my goals and background. The second was a Web Application Penetration Test where a Lead consultant gave me a computer and asked me to demonstrate, step by step, how I usually perform a Web Application Pentest. For each vulnerability found, they asked about its criticality, impact, solution, and how to explore it. Then there was an infrastructure pentesting with the main goal of reaching domain admin. Almost the same questions were asked: Impact, how to explore, and 'what do you know about <insert-topic-here>'.

Confirmed questions1 question
  • Using the nbtscan output, how would you identify the Domain Controller.

NCC Group Cybersecurity Consultant Interview Questions

Quoted word for word from NCC Group interview reports.

What are the mitigations for SSRF and where can they be found?

Read reports

Could you explain the distinctions between the SYSTEM and Administrator accounts?

Read reports

Can you detail the distinctions between encoding, hashing, and encryption?

Read report

What are the definitions of constrained delegation, unconstrained delegation, and RBCD, and how do they differ from each other?

Read report

Formats, difficulty and experience

Across all 23 NCC Group interview reports.

Interview formats

Technical 41.1%
Behavioral 30.4%
Coding 16.1%
Presentation 7.1%
Other 3.6%

Interview difficulty

Easy 13%
Average 60.9%
Difficult 26.1%

Candidate experience

Positive 78.3%
Negative 13%
Neutral 8.7%